Impact
The Linux kernel haptic driver incorrectly initializes values only for four recognized usages while writing data for every usage. An unhandled usage can capture an uninitialized value or residue from a previous usage, and hid_output_report() serializes that value into the effect’s report buffer. This behavior allows an attacker to read kernel memory content through the HID haptic report, potentially exposing sensitive information.
Affected Systems
All Linux kernel systems that have not been updated to include the fix in the haptic driver, regardless of kernel version. No specific vendor or version list is provided, but the issue appears in any kernel containing the vulnerable haptic module.
Risk and Exploitability
The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires local access to a HID haptic device and the ability to trigger a haptic effect. While it does not grant immediate privilege escalation, it can expose kernel memory to local users, which may aid in further attacks. The risk is therefore moderate, mainly affecting confidentiality rather than integrity or availability.
OpenCVE Enrichment